top of page
perceptive_background_267k.jpg

Improper Restriction of XML External Entity Reference vulnerability in XMLUtils.java in Slovensko.Digital Autogram allows remote unauthenticated attacker to con…

Published:

18 March 2026 at 23:00:00

Alert date:

19 March 2026 at 13:02:35

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Enterprise Applications

CVE-2026-3511 is an XML External Entity (XXE) vulnerability in XMLUtils.java of Slovensko.Digital Autogram application. The vulnerability allows remote unauthenticated attackers to conduct Server Side Request Forgery (SSRF) attacks and gain unauthorized access to local files on the filesystem. Exploitation requires victims to visit a malicious website that sends specially crafted XML documents to the /sign endpoint of the local HTTP server. The vulnerability affects the XML processing functionality and can lead to sensitive file disclosure and internal network reconnaissance through SSRF attacks.

Technical details

Mitigation steps:

Affected products:

Slovensko.Digital Autogram

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page